Skip to main content
Back to Home
Changelog

What changed, and when.

A dated record of user-visible corrections and additions to this site, including the ones where we had something wrong. We would rather show the correction history than pretend the copy was always right. For product releases (npm, PyPI), see the linked package registries directly; this page tracks the site itself.

2026-08-31

Boundary proof, surfaced

/boundary was live but reachable only from /verify. It is now linked from the homepage, the footer, and /trust, and /trust now points to it directly. Also corrected an unshipped "multi-tenant evidence isolation" claim on the cloud-governance solution page (see August 28), published a vulnerability disclosure policy at /security, and started this changelog.

2026-08-29

Boundary proof, published

/boundary lets anyone run a live check, against the deployed gateway, that a denied tool call never reaches the upstream server. It also names a real limitation plainly: the gateway does not yet publish its signing key independently of the bundle, so a self-check against a key taken from the bundle only shows internal consistency. The page says so directly rather than calling that provenance.

2026-08-28

Accessibility audit, extended

The axe-core audit covered 40 of 57 routes; the list is now derived automatically from the route tree instead of hand-maintained, and covers all 114 routes on the site.

2026-07-31

Contact form, fixed

Our own Content-Security-Policy was silently blocking submissions to Formspree since it shipped. Fixed, and the error message no longer blames the visitor's network for a failure that was ours.

2026-07-31

Six solution pages, corrected

Each implied a bundle-variant sample download that did not exist. Each now says plainly that the download is the same representative sample bundle offered site-wide.